Google Fined €403 Million by Irish DPC Over Location Data Privacy Violations
Ireland's **Data Protection Commission (DPC)** has imposed a substantial €403 million fine on **Google** for multiple violations of the **General Data Protection Regulation (GDPR)** concerning the processing of users' location data. The investigation, initiated in 2020, scrutinizes **Google**'s practices related to Web & App Activity, Location History, and Location Accuracy features.

The **DPC**'s inquiry stemmed from numerous complaints lodged by consumer rights organizations and focused on **Google**'s data handling between May 25, 2018, and February 4, 2020—a period falling under **GDPR**'s application.
### Scrutiny of Key Google Features
The investigation specifically targeted three **Google** features central to location data processing:
* **Web and App Activity**: This setting for **Google** Account holders enables the company to process user activity across its services, potentially including browsing and search histories, and location data.
* **Location History**: An opt-in service designed to track users carrying compatible mobile devices. It infers visited places, activities, and routes, displaying this information in a private **Google Maps Timeline**, even when the user is not actively using a **Google** service.
* **Location Accuracy**: An **Android** feature that enhances a device's positioning accuracy beyond **GPS** alone. This feature is operational regardless of whether a user possesses a **Google** Account.
### GDPR Violations Identified
The **DPC** concluded that **Google** processed location data via Web & App Activity and Location History without adhering to **GDPR**'s stringent requirements. Furthermore, the company failed to demonstrate compliance with **GDPR** principles in its processing of personal data through Location Accuracy.
Key allegations include **Google**'s failure to meet transparency obligations across all three features and the retention of location data collected through Web & App Activity and Location History for longer than necessary.
**Deputy Commissioner Graham Doyle** emphasized the gravity of these failures, stating, "[...] individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data." He added, "The retention of users’ location data for longer than necessary aggravated this loss of control."
### Penalties and Future Compliance
In response to these violations, the **DPC** has levied administrative fines totaling €403 million and mandated that **Google** bring its user data processing practices into compliance within the next six months. While the full decision has yet to be published, the **DPC** has committed to doing so in due course.
### Google's Response and Updated Practices
**Google** has acknowledged the ruling and stated that it has already updated its practices and policies, introducing mechanisms for easier location data management. A **Google** spokesperson clarified, "This case centers around historical policies that have since been updated. From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple."
The company highlighted the implementation of controls allowing users to define specific timelines for automatic data deletion. **Google Maps Timeline** information is now stored directly on the device, with data older than three months automatically removed. Additionally, **Google** asserts that it no longer saves precise device location in Web & App Activity, opting instead for an estimated general area.